Service targets: 99.9% uptime · 15-min response · 24/7 monitoringVancouver, BC · serving all of Canada · (604) 632-4959
ITIT ExpertsOPERATIONS / CANADA

SVC-06 / Secure

Managed Detection & Response

Human-led 24/7 threat detection and response across endpoints, identity and cloud, so an alert at 3 a.m. becomes a contained incident by breakfast.

Starting prices on this pageNo lock-inReviewed 2026-10-06

What Managed Detection & Response means in practice

Managed Detection and Response (MDR) combines modern detection tooling with analysts who investigate alerts, isolate compromised devices and guide remediation around the clock.

Buying endpoint software is not the same as operating it. Alerts that nobody triages are noise, and attackers often work evenings and weekends. MDR closes the gap between detection and response, which is where most breach damage occurs.

Problems this removes

  • Security alerts sitting unread in a console
  • Nobody on call when ransomware begins on a Friday night
  • Insurance applications asking for 24/7 monitoring you do not have
  • Compromised mailboxes noticed days later
  • Limited forensic data after an incident

What you get

  • 24/7 SOC triage of endpoint, identity and cloud alerts
  • Automated and analyst-approved device isolation
  • Business email compromise detection and mailbox rule review
  • Threat hunting against current attacker techniques
  • Incident reports with timeline, root cause and recommendations
  • Monthly security posture and alert summary

Typical platforms and tools

Microsoft Defender XDRSIEMEDREntra ID ProtectionLog retention
Target: alert triage inside 15 minutes, containment actions authorised by pre-agreed playbooks, monthly threat summary.

01How it connects with our other services

Managed Detection & Response works best as part of a coherent environment. Clients often pair it with Backup & Disaster Recovery, Mobile Device Management and Hardware Procurement & Lifecycle, which share the same monitoring, documentation and support desk. That integration avoids duplicate tools and finger-pointing between vendors, and it simplifies your monthly review because one report covers everything. You can start with one service and add others later, without renegotiating the whole relationship.

02Security, privacy and compliance

Every service we deliver follows least-privilege access, multi-factor authentication for administrators, logged changes and encrypted data in transit and at rest. For Canadian clients, we map managed detection & response work to PIPEDA, BC PIPA and customer security questionnaires, and we prefer Canadian data residency where it is available and practical. We prepare you for audits, but we do not issue certifications ourselves.

03Starting prices

As a guide, managed detection & response is priced as a defined project from $2,500 or as part of a managed plan of $89 to $199 per user per month. vCIO retainers start from $1,500 per month and security assessments from $1,900. A 10% launch discount applies, 5% GST is added, and there is no lock-in. Call (604) 632-4959 or email info@SAZ.ca for a free 30-minute consultation and a fixed quote.

04Our delivery method for managed detection & response

We treat every managed detection & response engagement as a small project with a start, an end and a measurable outcome. The sequence is assess, design, implement, validate and hand over. At each step you see exactly what is changing, why and when. Documentation is created as we go and delivered at the end so your organisation is not dependent on one engineer's memory. Target: alert triage inside 15 minutes, containment actions authorised by pre-agreed playbooks, monthly threat summary.

05How we measure managed detection & response

What gets measured improves. For managed detection & response we agree a small set of indicators in advance and report them monthly or quarterly. General service targets apply as well: a 99.9% uptime target on managed services, a 15-minute response target for priority tickets and round-the-clock monitoring. If a target is missed, we explain why and what is being done.

06Who Managed Detection & Response is right for

Managed Detection & Response suits Canadian organisations of 10 to 500 staff that want enterprise-grade discipline without an enterprise cost base. It is especially relevant to professional services, accounting & tax firms and startups & scale-ups teams, where the combination of regulated information, mobile workers and limited internal IT makes professional management of managed detection & response worthwhile. If you already have internal IT staff, we can deliver it as part of a co-managed arrangement.

07What happens in the first weeks

Early weeks focus on visibility and risk reduction. We inventory what exists, close the most urgent gaps and agree a plan for everything else. Staff receive short notices describing what will change, and leadership receives a first findings summary. By the end of the first month you will know the state of your managed detection & response, what it will cost to improve and what outcome to expect.

Frequently asked questions

How much does managed detection & response cost?

Projects start from $2,500 and managed plans from $89 to $199 per user per month. vCIO retainers begin at $1,500 per month and security assessments at $1,900. A 10% launch discount applies and GST of 5% is added.

Do we need to sign a long-term contract?

No. After onboarding the service is month to month with no lock-in, and you retain ownership of your documentation, configurations and data.

What is included in Managed Detection & Response?

Core deliverables include 24/7 SOC triage of endpoint, identity and cloud alerts, together with documentation, a hand-over session and reporting. Exact scope is confirmed in a written, fixed-price proposal after a short assessment.

Can managed detection & response be combined with our internal IT team?

Yes. We regularly deliver managed detection & response alongside in-house staff through our co-managed model, with responsibilities documented so there is no overlap or gap.

How long does managed detection & response take to implement?

Small engagements can be completed in one to two weeks; larger rollouts are phased over four to eight weeks. We schedule work outside business hours and keep a rollback plan for every change.

Call (604) 632-4959Email info@SAZ.caBook a consultation